4.6

CVSS4.0

CVE-2026-6539 - Notepad++ 8.9.3 Format String Injection via nativeLang.xml

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through communi…

πŸ“… Published: April 30, 2026, 8:31 p.m. πŸ”„ Last Modified: May 1, 2026, 7:30 p.m.

7.8

CVSS4.0

CVE-2026-39858 - Traefik: Forwarded alias spoofing top pre-auth decision bypass

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic targets only canoni…

πŸ“… Published: April 30, 2026, 8:26 p.m. πŸ”„ Last Modified: May 4, 2026, 4:58 p.m.

7.8

CVSS4.0

CVE-2026-35051 - Traefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue …

πŸ“… Published: April 30, 2026, 8:26 p.m. πŸ”„ Last Modified: May 1, 2026, 9:20 p.m.

6.8

CVSS4.0

CVE-2026-40951 - Memory corruption in Secure Access Windows clients prior to 14.50

CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service.

πŸ“… Published: April 30, 2026, 8:22 p.m. πŸ”„ Last Modified: May 4, 2026, 6:54 p.m.

4.8

CVSS4.0

CVE-2026-41174 - Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetesCRD.allowCrossNamespace=false, Traefik correctly rejects dir…

πŸ“… Published: April 30, 2026, 8:20 p.m. πŸ”„ Last Modified: May 4, 2026, 2 p.m.

7.1

CVSS4.0

CVE-2026-40950 - Buffer overflow in the Secure Access server prior to 14.50

CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service

πŸ“… Published: April 30, 2026, 8:19 p.m. πŸ”„ Last Modified: May 5, 2026, 2:32 a.m.

6

CVSS4.0

CVE-2026-28532 - FRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser Functions

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointe…

πŸ“… Published: April 30, 2026, 8:17 p.m. πŸ”„ Last Modified: May 1, 2026, 7:46 p.m.

6.8

CVSS4.0

CVE-2026-40949 - Buffer overflow in Windows clients prior to 14.50

CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.

πŸ“… Published: April 30, 2026, 8:16 p.m. πŸ”„ Last Modified: May 5, 2026, 2:32 a.m.

5.9

CVSS4.0

CVE-2026-33452 - Buffer overflow in Windows clients prior to 14.50

CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to β€˜blue screen’ the system.

πŸ“… Published: April 30, 2026, 8:12 p.m. πŸ”„ Last Modified: May 5, 2026, 2:31 a.m.

8.6

CVSS4.0

CVE-2026-7435 - SSCMS v7.4.0 SQL Injection via stl:sqlContent queryString

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbit…

πŸ“… Published: April 30, 2026, 8:09 p.m. πŸ”„ Last Modified: May 4, 2026, 2:16 p.m.
Total resulsts: 349182
Page 184 of 34,919
Β« previous page Β» next page
Filters